logo

Living Off Trusted Sites: Zoom service abuse to deliver credential phishing attack · Blog · Sublime Security

ID: da8051de-29a2-57ad-a7ec-62bd6a8eaad9

STIX ID: report--da8051de-29a2-57ad-a7ec-62bd6a8eaad9

Feed Name: Sublime Security Blog

Threat Score
55/100

Date Published: 2025-10-22

Date Updated: 2026-05-01

...
...

This report describes a credential-phishing campaign that abused Zoom Events and Zoom Docs to host a man-in-the-middle phishing page impersonating Microsoft 365 (using a malicious office.regencyoutdor.com link). The attack leverages living-off-the-trusted-sites techniques to appear legitimate and aims to steal user credentials; Sublime's AI detection flagged and prevented the attack while highlighting suspicious sender metadata, vague language, and mismatched hostnames.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.